Oh nooo.. WORM keeps e-mailing! Please Help ;-)

Discussion in 'Malware Help (A Specialist Will Reply)' started by scooterd, Mar 24, 2006.

  1. scooterd

    scooterd Private E-2

    Hi Friends,

    McAfee window keeps popping up stating many e-mails shooting out due to worm. I have already followed the instructions and done all the RUN FIRST stuff (both in and out of safe mode/as instructed), including (full scans, listed in random order):
    McAfee Anti-Virus
    CCleaner
    Ad-Aware
    SpyBot
    CWshredder
    MS Malicious Soft. Rem Tool
    Windows Defender
    Ewido Scan
    BitDefender
    Active Panda Scan

    Detected and removed lots of stuff (including Smitfraud-C), and am attaching my logs/reports. Help would be greatly appreciated at this point, as it's gobbling up fix-attempt hours like crazy ;-(

    Thanks!

    S.D.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Per step 7 instructions we need HJT logs from normal boot mode not safe mode. Also I need your Bitdefender log.

    Question: Do you see the below files?

    C:\WINDOWS\SYSTEM32\taskdir.dll
    C:\WINDOWS\SYSTEM32\taskdir.exe
    C:\WINDOWS\SYSTEM32\parad.raw.exe
     
  3. scooterd

    scooterd Private E-2

    Hello,

    Thanks so much for the reply. I am away from that computer right now, but I recall seeing at least one of those files (I am pretty sure). I'll go back to that computer soon and if I see any of those files, should I delete them or anything?

    Will try to send you those logs soon too. (Actually BitDefender and IE kept shutting down in Normal Mode before, but I'll try it again now that I ran all those tools). If Bit defender won't run in Normal mode, what should I do?

    Thanks again! ;-)

    S.D.
     
  4. scooterd

    scooterd Private E-2

    Hello again,

    I ran BitDefender again and it didn't find anything. The computer seems to be working well so far.

    Earlier, you asked me "Question: Do you see the below files?"
    C:\WINDOWS\SYSTEM32\taskdir.dll - (was there earlier, but gone now)
    C:\WINDOWS\SYSTEM32\taskdir.exe - (no)
    C:\WINDOWS\SYSTEM32\parad.raw.exe - (no)

    At first I saw this one: C:\WINDOWS\SYSTEM32\taskdir.dll
    (and I also remember BitDefender saying it found it earlier.)

    But now it's gone. (and BitDefender now reports finding nothing.)

    I have however, attached new Active Scan and HJT logs, to see if there's anything else that you recommend I do to make suyre I am clean and the problem won't come back.

    Thanks again! ;-)

    S.D.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you change the name of the recycle bin from Recycler to Recycled?

    Delete the below files:
    C:\Recycled\Dc24.txt
    C:\Recycled\Dc25.txt
    C:\Recycled\Dc29.txt


    Make sure viewing of hidden files is enabled (per the tutorial).

    You will need to shut down Windows Defender before doing the below and also when you restart Windows Defender (or after a reboot when it runs again) it may give a message about a change to one of your start or main pages. Make sure you accept/approve the change or the changes will not be made.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
    O2 - BHO: (no name) - {77701e16-9bfe-4b63-a5b4-7bd156758a37} - (no file)ce.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\Windows\system32\ce.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST)
    .

    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Now reboot in normal mode and post a new HJT log.

    Make sure you tell me how things are working now.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  6. scooterd

    scooterd Private E-2

    Hello again,

    (You asked:) Did you change the name of the recycle bin from Recycler to Recycled?

    No, but the entire directory and files listed below were no longer there.

    Delete the below files: (were not there to remove)
    C:\Recycled\Dc24.txt
    C:\Recycled\Dc25.txt
    C:\Recycled\Dc29.txt

    Note: C:\Windows\system32\ce.exe" was not to be removed either (and I'm sure I was wiewing all files, none hidden)

    New HJT log attached, thanks again!

    S.D.
     

    Attached Files:

  7. scooterd

    scooterd Private E-2

    ...forgot to mention, computer "seems" to be running well now.

    Just awaiting your final word after you get to peek at the last HJT log I posted, to make sure all looks good or to see if there's any last things that you suggest I do. (After all this and all the e-mails it was shooting out, it would stink if the problem came back, so better safe than sorry ;-)

    Thanks again!

    S.D.:rolleyes:
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds